نحن نبحث عن مستشار GRC (الحوكمة، المخاطر والامتثال) ذو خبرة في إدارة امتثال الأمن information security، سيؤدي المرشح المثالي دوراً رئيسياً في ضمان الامتثال التنظيمي، إدارة مخاطر الأمن، وتحسين الحوكمة داخل المنظمة
المسؤوليات الرئيسية: تطوير، تنفيذ، والحفاظ على أطر أمن المعلومات والامتثال متوافقة مع المعايير الصناعية مثل ISO 27001، NIST، CBUAE، SAMA،
دعم تطوير السياسات والرقابة على الامتثال
إنشاء وتحديث سياسات وإجراءات تكنولوجيا المعلومات لضمان الامتثال للوائح البنك والمعايير الصناعية.
العمل مع رؤساء الأقسام لتحديد متطلبات السياسة ومعالجة أي قضايا محتملة.
تصميم وتنفيذ إجراءات فعّالة لتحسين الكفاءة التشغيلية والإنتاجية.
تطوير وثائق معيارية ونماذج وتنسيقات بيانات لاستخدام متسق داخل قسم تكنولوجيا المعلومات.
اقتراح فريق حوكمة البنك لتطبيق أفضل الممارسات والمعايير على جميع عمليات تكنولوجيا المعلومات.
المشاركة في كل من التدقيقات الخارجية والداخلية المتعلقة بقسم تكنولوجيا المعلومات ووحداته المرتبطة.
إجراء فحوصات فورية منتظمة عبر وحدات تكنولوجيا المعلومات المختلفة لضمان الالتزام بسياسات وإجراءات IT.
تحليل متطلبات ومواصفات المشروع لتطوير استراتيجية اختبار واضحة وفعالة.
إنشاء خطة اختبار شاملة تفصل النطاق والأهداف والجدول الزمني ونهج الاختبار.
التنسيق مع أصحاب المصالح بالبنك للمساعدة في تطوير حالات اختبار ونصوص تفصيلية بناءً على المتطلبات ومواصفات التصميم.
التنسيق مع أصحاب المصالح بالبنك واقتراح الأساليب لإنتاج بيانات اختبار تغطي نطاقاً من السيناريوهات لتنفيذ اختبار شامل.
التنسيق مع أصحاب المصالح بالبنك المعنيين وتنفيذ حالات الاختبار لضمان أن البرنامج يعمل كما هو مقصود.
تحديد العيوب وتوثيقها، بما في ذلك الأخطاء الوظيفية ومشكلات الأداء.
التنسيق والعمل مع فريق تكنولوجيا المعلومات لتسجيل العيوب بتفاصيل شاملة مثل خطوات التكرار، الشدة، واللقطات ذات الصلة، وإبلاغ هذه القضايا إلى فرق الدعم والبائعين للحل.
إعداد تقارير موجزة عن الاختبار تقدم نظرة عامة على أنشطة الاختبار، حالة العيوب، وجودة البرنامج بشكل عام
التعاون مع أصحاب المصلحة في تكنولوجيا المعلومات لتقييم طلبات التغيير، تقييم المخاطر المرتبطة وتحديد أولويات التغييرات.
تسهيل اجتماعات مجلس استشاري التغيير (CAB)، وضمان مراجعة جميع التغييرات واعتمادها من قبل CAB.
مراقبة وتقرير عن مقاييس التغيير، بما في ذلك معدلات النجاح، التغييرات الفاشلة، والتأثير الكلي.
ضمان توثيق أنشطة الإطلاق بشكل كامل، وتوصيلها، وتوافقها مع استراتيجية الإطلاق الكلية.
تتبع وإدارة تبعيات الإصدار، وحل أي تعارضات أو مشكلات قد تنشأ.
توفير تقارير وتحديثات منتظمة حول مقاييس التغيير والإصدارات للإدارة وأصحاب المصالح.
إجراء تقييمات ذاتية لمخاطر وتدقيق الإطار الرقابي لتكنولوجيا المعلومات (RCSAs) والحفاظ على التوثيق الشامل.
تطوير استراتيجيات وخطط التخفيف من المخاطر، وتقديم التوصيات والإجراءات التصحيحية لمعالجة المخاطر المحددة.
إجراء مراجعات مخاطر IT الشهرية والتقرير عن حالة مخاطر تكنولوجيا المعلومات.
مراجعة سجل المخاطر بشكل منتظم والمتابعة مع الفرق المعنية لتنفيذ خطط التخفيف حتى الحلول.
إنشاء وصيانة التقارير ولوحات القيادة لتتبع حالة المخاطر والتواصل عنها.
إعداد ونشر تقارير منتظمة ولوحات القيادة والعروض التقديمية حول حالة المشاريع والقطاع أمام الإدارة العليا.
إجراء عمليات تدقيق دورية في عمليات المشروع والحوكمة لضمان الإبلاغ الشفاف عن التقدم، القضايا، والمخاطر.
مراقبة أداء المشروع لتحديد ومعالجة المشاكل المحتملة.
ضمان الامتثال لجميع السياسات ذات الصلة طوال عملية تسليم المشروع.
التعاون مع أصحاب المصلحة الداخليين لمعالجة المخاطر والقضايا والتحديات المتعلقة بالمشروع.
العمل مع فريق تكنولوجيا المعلومات لتتبع وحل المخاطر التي تم تحديدها أثناء تنفيذ المشروع.
We are seeking an experienced GRC (Governance, Risk, and Compliance) Consultant with expertise in Information Security Compliance Management, The ideal candidate will play a key role in ensuring regulatory compliance, managing security risks, and enhancing governance within the organization
Key Responsibilities: Develop, implement, and maintain Information Security and Compliance frameworks aligned with industry standards such as ISO 27001, NIST, CBUAE, SAMA,
Support Policy Development and Compliance Oversight
Create and update IT policies and procedures to ensure compliance with bank regulations and industry standards.
Work with department heads to determine policy requirements and address any potential issues.
Design and implement efficient procedures to improve operational effectiveness and productivity.
Develop standard documentation, templates, and data formats for consistent use within the IT Division.
Suggest Bank Governance team to apply best practices and standards to all IT processes.
Participate in both external and internal audits related to the IT Division and its associated units.
Conduct regular spot checks across various IT units to ensure adherence to IT policies and procedures.
Analyse project requirements and specifications to develop a clear and effective testing strategy.
Create a comprehensive test plan that details the scope, objectives, schedule, and testing approach.
Coordinate with the bank respective stakeholders to help Develop detailed test cases and scripts based on requirements and design specifications.
Coordinate with the bank respective stakeholders and suggest approaches to Generate test data to cover a range of scenarios for thorough test execution.
Coordinate with the bank respective stakeholder to Execute test cases to ensure the software operates as intended.
Identify and document defects, including functional errors and performance issues.
Coordinate to and work with IT team to Log defects with comprehensive details, such as reproduction steps, severity, and relevant screenshots, and report these issues to the support and vendor teams for resolution.
Prepare test summary reports that provide an overview of testing activities, defect status, and overall software quality
Collaborate with IT stakeholders to evaluate change requests, assess associated risks, and prioritize changes.
Facilitate Change Advisory Board (CAB) meetings, ensuring all changes are reviewed and approved by the CAB.
Monitor and report on change metrics, including success rates, failed changes, and overall impact.
Ensure release activities are thoroughly documented, communicated, and aligned with the overall release strategy.
Track and manage release dependencies, resolving any conflicts or issues that may arise.
Provide regular reports and updates on change and release metrics to management and stakeholders.
Conduct IT risk and control self-assessments (RCSAs) and maintain comprehensive documentation.
Develop risk mitigation strategies and plans, and present recommendations and corrective actions to address identified risks.
Perform monthly IT risk reviews and report on the status of IT risks.
Regularly review the risk register and follow up with relevant teams on the implementation of risk mitigation plans until resolution.
Create and maintain reports and dashboards to track and communicate the status of risks.
Prepare and publish regular reports, dashboards, and presentations on project and portfolio status for senior management.
Conduct periodic audits of project processes and governance to ensure transparent reporting of progress, issues, and risks.
Monitor project performance to identify and address potential problems.
Ensure compliance with all relevant policies throughout the project delivery process.
Collaborate with internal stakeholders to address risks, issues, and challenges related to the project.
Work with the IT team to track and resolve risks identified during project implementation.
Tanqeeb.com هو محرك البحث عن الوظائف الأول فى الوطن العربى الذى يجمع لك الوظائف المناسبة من مختلف مواقع التوظيف الآخرى فى مكان واحد !